As explained in #3828, rebroadcast of transactions paying the wallet (but not spending any wallet inputs) is a privacy leak, since anyone can generate these, choose a low fee, and observe who rebroadcasts them. While it is somewhat intuitive that submitting transactions has privacy implications - at least until confirmation - this is manageable by various strategies (switching to privacy networks for a while, using private broadcast, making sure it confirms before rebroadcast). However, I find it rather unexpected that just passively running a node with a wallet loaded can lead to a loss of privacy as well.
This PR stops rebroadcasting transactions that don't spend any wallet inputs. For the same reason, they are also no longer re-added to the mempool on startup or after an import: otherwise our node might be the only one still having a transaction the rest of the network has dropped, which can be detected with active probing (e.g. by submitting a child).
This does have the trade-off that receivers (who have an incentive to get paid) will now need to manually resubmit transactions if the transaction doesn't confirm and the sender doesn't rebroadcast, but I think it is worth the privacy benefit.
An alternative approach is #36380, although these could also be combined (make rebroadcast optional, but never rebroadcast non-originating transactions)
Fixes #3828